VDB
BDU%3A2019-02957
BDU%3A2019-02957
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость реализации сетевого протокола HTTP/2 операционных систем Windows, сервера nginx, сетевых программных средств netty, Envoy, SwiftNIO, программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Сообщество свободного программного обеспечения, Node.js Foundation, NGINX Inc., Apple Inc., Apache Software Foundation | Windows 10, Windows 10 1607, Windows 10 1703, Windows Server 2016, Windows Server 2016 (Server Core installation), Debian GNU/Linux, Windows 10 1709, Windows 10 1803, Windows Server 1803 (Server Core Installation), Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 1903, Windows Server 1903 (Server Core Installation), Envoy, Node.js, nginx, SwiftNIO, netty |
Timeline
- Aug 22, 2019 CVE Published
- Mar 23, 2021 CVE Updated
- Mar 23, 2026 Security Advisory
References
- https://www.opennet.ru/opennews/art.shtml?num=51279 url
- https://blog.getambassador.io/multiple-http-2-vulnerabilities-in-envoy-proxy-59351babb3aa url
- https://support.apple.com/en-us/HT210436 url
- https://security-tracker.debian.org/tracker/CVE-2019-9518 url
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md url
- https://netty.io/news/2019/08/13/4-1-39-Final.html url
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-9518 advisory
- https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/ advisory
- http://mailman.nginx.org/pipermail/nginx-announce/2019/000247.html advisory